6.9

CVE-2025-43735 Reflected XSS in google_widget

Description

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal and Liferay DXP allows an remote non-authenticated attacker to inject JavaScript into the google_gadget.

Severity